Jump to content

MAJOR SAFETY ISSUE FOUND (data-encryption related)


Go to solution Solved by agsteele,

Recommended Posts

Hi there, I'm a premium Evernote user and I think I've ran into a major safety issue.

I was wondering if my encrypted data were safe enough, and asked myself what happens with the history of change regarding notes which contain encrypted data.

(For those who don't know, this is a premium function allowing to see earlier version of a Note, automatically created).

Well, I've found out that that through this view UNCRYPTED DATA ARE EXPOSED AND CAN BE SEEN WITH NO PASSWORD NEEDED.

This is a major issue that can compromise users' safety and needs to be addressed immediately. In the meantime, I suggest every user to store their sensitive data elsewhere, while waiting for this issue to be fixed.

 

 

Link to comment
5 hours ago, Matteo Contigliozzi said:

Hi there, I'm a premium Evernote user and I think I've ran into a major safety issue.

I was wondering if my encrypted data were safe enough, and asked myself what happens with the history of change regarding notes which contain encrypted data.

(For those who don't know, this is a premium function allowing to see earlier version of a Note, automatically created).

Well, I've found out that that through this view UNCRYPTED DATA ARE EXPOSED AND CAN BE SEEN WITH NO PASSWORD NEEDED.

This is a major issue that can compromise users' safety and needs to be addressed immediately. In the meantime, I suggest every user to store their sensitive data elsewhere, while waiting for this issue to be fixed.

 

 

Yeah, this has been a known problem for as long as EN exists which has been discussed several times on the forums.

There are two workarounds to prevent unencrypted history of your sensitive data:

  • Encrypt first a small dummy text and then change it to the actual text
  • Create and encrypt your text with disconnected network

I hope Bending Spoons will finally solve this properly

  • Like 1
Link to comment
  • Evernote Expert
  • Solution

The Evernote text encryption has long been considered inadequate.  Better to encrypt in an external application.  I have used AxCrypt very successfully but it is a paid for app if you want to be able to work across devices.

Saferoom is another application that I have used and offers a free level of access and is more tightly integrated with Evernote.

Link to comment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...